Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:20412
HistoryJun 03, 2019 - 12:25 a.m.

Side-channel Attack

2019-06-0300:25:00
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
9

0.001 Low

EPSS

Percentile

33.2%

httpd is vulnerable to side-channel attack. An implementation flaw was discovered in multiple cryptographic libraries that allows a side-channel based attacker to recover ECDSA or DSA private keys. When these cryptographic libraries use the private key to create a signature, such as for a TLS or SSH connection, they inadvertently leak information through memory caches. An unprivileged attacker running on the same machine can collect the information from a few thousand signatures and recover the value of the private key.

References